CVE-2025-9412 | lostvip-com ruoyi-go up to 2.1 DictDataDao.go SelectListByPage orderByColumn/isAsc sql injection
A vulnerability categorized as critical has been discovered in lostvip-com ruoyi-go up to 2.1. This affects the function SelectListByPage of the file modules/system/dao/DictDataDao.go. The manipulation of the argument orderByColumn/isAsc results in sql injection.
This vulnerability is reported as CVE-2025-9412. The attack can be launched remotely. Moreover, an exploit is present.
The vendor was contacted early about this disclosure but did not respond in any way.